[RFC PATCH v3 26/27] KVM: SVM: Do not intercept exceptions for Secure AVIC guests
From: Naveen N Rao (AMD)
Date: Wed Jul 08 2026 - 02:44:51 EST
From: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
In Secure AVIC mode, exceptions cannot be injected by KVM as the VMCB
EVENTINJ field is ignored. As such, do not intercept exceptions since
KVM will be unable to re-inject those back into the guest. The only
exception is #MC since that needs to be handled in the host, so
explicitly force-enable #MC interception.
Signed-off-by: Neeraj Upadhyay <Neeraj.Upadhyay@xxxxxxx>
Co-developed-by: Naveen N Rao (AMD) <naveen@xxxxxxxxxx>
Signed-off-by: Naveen N Rao (AMD) <naveen@xxxxxxxxxx>
---
arch/x86/kvm/svm/sev.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c
index 707537ad7271..7c9c25135df8 100644
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -4862,6 +4862,22 @@ static void sev_es_init_vmcb(struct vcpu_svm *svm, bool init_event)
/* Can't intercept XSETBV, HV can't modify XCR0 directly */
svm_clr_intercept(svm, INTERCEPT_XSETBV);
+ if (snp_is_secure_avic_enabled(svm->vcpu.kvm)) {
+ /* Clear all exception intercepts since we can't inject those */
+ for (int i = 0; i < NUM_EXCEPTION_VECTORS; i++)
+ clr_exception_intercept(svm, i);
+
+ /*
+ * Note that #MC is always intercepted by hardware in Secure
+ * AVIC mode, so mark #MC as intercepted to stay consistent
+ * with the hardware behavior. From the APM:
+ * "In Secure AVIC mode hardware treats physical INTR, NMI,
+ * INIT, and #MC events as intercepted regardless of the
+ * corresponding intercept bit values in the VMCB."
+ */
+ set_exception_intercept(svm, MC_VECTOR);
+ }
+
/*
* Set the GHCB MSR value as per the GHCB specification when emulating
* vCPU RESET for an SEV-ES guest.
--
2.54.0